Reliable multi-tenant auto setup audit capability
Find a file
tegwick de9e3abe5f AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total
T02. deploy/attest-cronjob.yaml: daily at 03:17 UTC against the 168h window,
its own ServiceAccount, and a Role reaching exactly one named ConfigMap —
get/update/patch, no create, no list. audit_core/attest_publish.py does the
publish in stdlib; the image carries no kubectl, and adding one to an audit
receiver's image to write a single file is the worse trade.

Three refusals, all deliberate:

  The producer is not the receiver. A receiver that could rewrite its own
  attestation could forge it. audit-core-egress is now scoped to
  component: receiver and a separate audit-core-attest-egress carries the 6443
  rule, so the receiver never gains API-server reach. Asserted by test.

  It refuses to publish over a broken chain. A fresh head written over a break
  replaces an honest chain_break with a fresh-looking attestation. Stale
  degrades the claim visibly; false does not.

  Mounted as a directory, not subPath. Found while writing the manifest: a
  subPath ConfigMap mount is resolved once at pod start and never updates, so
  the daily attestation would land in the ConfigMap and never reach the running
  receiver — tamper_evidence would age out to false while the job reported
  success every night, silent in both directions.

The offsite copy stays an operator step. audit-core holds no Nextcloud
credential and should not acquire one to publish a hash, so docs/integrity.md
states the bound plainly: until that copy exists the delivered control defends
against a database owner, not a cluster owner, and no stronger claim may be
made from it.

T10. layer.yaml lists four infrastructure contacts — platform-pg, state-hub,
kube-apiserver, the container registry — each with its role and whether another
layer reads it. tooling_contacts stays [], which is true under §5 as written;
the companion's totality request is met by the uncatalogued list rather than by
inventing a Tooling row. tests/test_layer_conformance.py derives the egress
destinations from the manifests and the registry from the pinned digests, so a
new contact appearing in deploy/ without a row fails the test rather than
waiting for a reviewer to notice.

Applying the manifests remains an operator action; nothing here was applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nb7Q6ZmXppNDkTWytfYqfv

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2069992@bnt-lap001
Assistant-Session: 167dd7f8-2a25-4be1-aa46-3b6f1a5f94c6
2026-09-10 16:39:20 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 5) 2026-07-08 19:50:55 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:28:40 +02:00
.repo-manager Track repo-manager index and the TAMQ introduction 2026-08-29 14:45:26 +02:00
audit_core AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
data/capability Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
deploy AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
docs AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
evidence Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
history Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
intakes AUDIT-WP-0010 T01/T03/T04 — admit tenant-engine, and the envelope does not match 2026-09-10 16:34:45 +02:00
registry Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
scripts feat(AUDIT-WP-0008): add T02 synthetic load driver 2026-08-22 16:46:31 +02:00
spec Added PRD for what we want to do 2026-06-01 23:38:26 +02:00
tests AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
workplans AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-10 15:16:13 +02:00
.dockerignore Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
.gitignore Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:20:39 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:24 +02:00
Containerfile Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
INTENT.md Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
layer.yaml AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:53:10 +02:00
Makefile Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
pyproject.toml Add the PostgreSQL audit backend and a shared conformance suite 2026-08-10 17:09:46 +02:00
README.md Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
SCOPE.md AUDIT-WP-0009-T03/T09 — evidence_kind, and approval-engine's registration inputs 2026-09-06 22:31:37 +02:00
TamqMessagingIntroduction.md Track repo-manager index and the TAMQ introduction 2026-08-29 14:45:26 +02:00
tenancy.yaml evidence(AUDIT-WP-0008): establish E2 target pass 2026-08-23 00:26:32 +02:00
WORK-RECORDS.md chore(consistency): write back hub ids for AUDIT-IN-0003 and T11 [auto] 2026-09-10 15:16:23 +02:00

Reliable multi-tenant auto setup audit capability

Production on railiance01 (AUDIT-WP-0005): PostgreSQL custody, digest-pinned image, operator procedures in docs/operator-runbook.md. Manifests live in deploy/.

Backend contract

The pluggable backend interface, event schema (audit-core.event.v1alpha1), retention policy, and migration path from the mock file backend are documented in docs/audit-backend-contract.md.

Development Mock Backend

The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.

By default it writes JSONL audit events to:

/tmp/audit-core/audit-YYYYMMDDTHH.jsonl

Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.

Example:

python3 -m audit_core emit \
  --source openbao \
  --action openbao.authenticated_readiness_proof \
  --resource openbao/openbao-0 \
  --outcome success \
  --detail file_audit_visible=true \
  --detail backend=mock-file

Cleanup:

python3 -m audit_core cleanup

Make targets:

make test
make mock-audit-smoke
make mock-audit-cleanup

Environment:

  • AUDIT_CORE_MOCK_DIR: override the output directory.
  • AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.